<img src="https://secure.office-information-24.com/785669.png" style="display:none;">
Glossary

Internal Audit

Also called: First-Party Audit
An internal audit is a planned, systematic evaluation performed by an organization's own trained personnel to determine whether its quality management system conforms to its own requirements and to applicable standards, and whether the system is effectively implemented and maintained. Internal audits are sometimes called first-party audits to distinguish them from external audits performed by outside parties. Internal auditors must be independent of the activity they are auditing so that results remain objective. 

Quick facts

Category Self-assessment and continual improvement
Used by Manufacturing, medical devices, pharmaceuticals, aerospace, automotive and other regulated industries
Also called First-party audit
Related standards ISO 9001, ISO 13485, AS9100, IATF 16949, ISO 19011
Related processes Audit management, CAPA, nonconformance, management review, document control
Semantic match internal audit process, first-party audit, ISO 9001 internal audit, internal quality audit program

What is Internal Audit?

An internal audit is a first-party audit, meaning it is performed by the organization on itself rather than by an outside customer or certification body. Trained internal auditors examine processes, records and practices to determine whether they conform to the organization's documented procedures, to applicable standards such as ISO 9001, and to customer or regulatory requirements.

Internal audits are planned in advance as part of an audit program that defines scope, criteria, frequency and responsible auditors. Auditors gather objective evidence through interviews, observation of work being performed, and review of records, then compare that evidence against the applicable requirements.

A defining requirement of internal audits is auditor independence. Auditors should not audit their own work, since doing so risks compromising the objectivity of the findings.

Why is Internal Audit important?

Internal audits give an organization an honest, structured look at whether its quality system works in practice, not just on paper. They frequently surface gaps between documented procedures and actual day-to-day practice before those gaps become customer complaints, regulatory findings or product failures.

Because internal audits are self-initiated, they allow an organization to find and fix issues on its own timeline, rather than waiting to be told by a customer or certification body. This proactive discovery is a core expectation of ISO 9001 and related standards.

Internal audit findings feed directly into corrective action and management review, connecting day-to-day process verification to leadership-level decisions about where to invest in improvement.

How does Internal Audit work?

A typical internal audit follows these steps:

  1. Program planning. Schedule audits across the year based on risk, importance and prior results.
  2. Scope and criteria. Define which process or area will be audited and against which requirements.
  3. Auditor assignment. Select a trained, independent auditor for the area being examined.
  4. Evidence gathering. Interview personnel, observe work, and review records and documents.
  5. Findings. Document conformances, nonconformances and opportunities for improvement.
  6. Reporting. Communicate results to relevant management without undue delay.
  7. Corrective action. Investigate and resolve nonconformances through the CAPA process.
  8. Follow-up. Confirm corrective actions were completed and effective before closing the audit.

Internal Audit vs. Management Review

Comparison Internal Audit Management Review
Purpose Verify conformance of processes and records to requirements Evaluate the overall suitability, adequacy and effectiveness of the QMS
Performed by Trained, independent internal auditors Top management
ISO 9001 reference Clause 9.2 Clause 9.3
Typical input to the other Audit results are a required input to management review May direct audit program priorities for the coming period

Real-world examples of Internal Audit

A pharmaceutical manufacturer schedules an internal audit of its batch record process. The auditor finds that some entries are made after the fact rather than in real time and opens a corrective action to reinforce contemporaneous recordkeeping.

An electronics manufacturer's internal auditor reviews the calibration program and discovers several instruments are past their due date. The finding triggers an immediate containment action and a broader review of calibration scheduling.

A medical device company uses internal audit results, aggregated across a full year, to identify that training compliance is a recurring weak point across departments, prompting a management review discussion on training resources.

Regulations and standards related to Internal Audit

ISO 9001 Clause 9.2 requires organizations to plan, establish, implement and maintain an internal audit program that considers the importance of the processes involved, changes affecting the organization, and the results of previous audits, and to select auditors who ensure objectivity and impartiality of the audit process.

ISO 13485 and IATF 16949 carry similar internal audit requirements adapted to medical device and automotive quality systems, and AS9100 extends internal audit expectations to aerospace-specific processes. ISO 19011 provides widely used guidance on auditing management systems, including auditor competence and program management, though it is a guidance standard rather than a certifiable requirement.

Internal audit clause 9.2 has historically been among the more frequently cited nonconformances in ISO 9001 and AS9100 certification audits, often due to incomplete audit programs or auditors lacking independence.

Required by

How QT9 helps with Internal Audit

QT9 QMS internal audit capabilities

  • Build and manage an internal audit schedule with automated reminders.
  • Create custom checklists tailored to ISO, FDA or customer-specific requirements.
  • Auto-generate CAPAs directly from internal audit findings.
  • Assign auditors and track independence and competence records.
  • Maintain a complete, timestamped audit trail for every internal audit.
  • Report internal audit trends and overdue items on real-time dashboards.

Request an Internal Audit Demo Explore Audit Management Software →

See QT9 Software in Action

Discover how QT9 Software helps manufacturers improve efficiency, strengthen compliance and connect quality management and ERP processes within one integrated platform.

Common mistakes with Internal Audit

Common internal audit mistakes include assigning auditors to review their own work or department, which undermines objectivity, and treating the internal audit as a paperwork exercise rather than a genuine evaluation of practice.

Other problems include building an audit schedule that does not account for risk or prior findings, failing to report results to management without undue delay, and not following through on corrective actions once a nonconformance is identified.

Frequently asked questions

They are the same thing described two ways. An internal audit is called a first-party audit because it is performed by the organization on itself, as opposed to a second-party audit performed by a customer or a third-party audit performed by a certification body.
Internal audits should be conducted by personnel trained in audit techniques and the applicable requirements, and who are independent of the specific activity being audited so the results remain objective.
ISO 9001 does not specify a fixed frequency. It requires organizations to establish an audit program with a frequency based on the importance of the processes involved, changes affecting the organization, and the results of previous audits.
The organization must take appropriate correction and corrective action without undue delay, typically by opening a formal corrective action or CAPA record to investigate the root cause and prevent recurrence.
Any organization certified to ISO 9001 or a related standard must maintain an internal audit program regardless of size, though the scale and complexity of the program can be tailored to the size and risk profile of the organization.
Organizations should retain documented information as evidence of the audit program and its results, typically including the audit plan, scope and criteria, findings, and any resulting corrective actions.

Related quality management terms

Related content

Ready to Transform Your Business?

See how QT9 Software helps manufacturers simplify operations, improve traceability and drive continuous improvement with integrated quality management and ERP software.

Last reviewed: July 21, 2026